QChatPQC
Service 03

Migration-Roadmap Generation

Answer a couple of questions and get a phased PQC migration plan, sequenced against NIST's finalized standards and the 2035 federal migration deadline.

Organization size
Priority systems
Phase 1Discover (0-3 months)
  • Build a cryptographic inventory: algorithms, key sizes, certificate authorities, libraries, and where each is used.
  • Classify data by confidentiality horizon to flag 'harvest now, decrypt later' exposure.
  • Identify systems and vendors on your critical path, and request their PQC support timelines.
Phase 2Prioritize (2-4 months)
  • Rank systems by risk: long-lived secrets and public-facing key exchange first.
  • Assign owners and budget for the highest-priority items identified in Phase 1.
  • Confirm your CA's roadmap for issuing ML-DSA / hybrid certificates.
Phase 3Pilot (3-6 months)
  • Stand up a hybrid ECDH + ML-KEM (FIPS 203) key-exchange pilot on a non-critical service.
  • Validate performance impact: handshake latency, message size, CPU overhead.
Phase 4Roll out (6-18 months)
  • Migrate prioritized systems in waves, favoring cryptographic agility so future algorithm swaps don't require re-architecture.
  • Track progress against FIPS 203/204/205 conformance and internal milestones.
Phase 5Verify & sustain (ongoing)
  • Validate implementations against NIST CAVP/CMVP where applicable.
  • Re-run the cryptographic inventory quarterly; treat crypto agility as a standing engineering requirement, not a one-time project.
  • Track NIST updates: FN-DSA (Falcon) finalization, HQC (FIPS pending), and additional signature on-ramp candidates.